Skip to main content
Category: ISMS Clauses and Planning

Improvement (Clause 10)

Also known as: Clause 10, Improvement Clause, Continual Improvement (Clause 10)
Simply put

Improvement (Clause 10) is a requirement in ISO management system standards that asks an organization to keep making its processes and systems better over time. In practice, this means identifying problems when things go wrong, fixing them and their underlying causes, and continually looking for ways to enhance performance. It reflects the idea that a management system should not stay static but should evolve as needs and circumstances change.

Formal definition

Clause 10 is the 'Improvement' clause found within the requirements of ISO management system standards, which share a common high-level structure. It typically addresses the handling of nonconformities and associated corrective actions, as well as continual improvement of the management system's suitability, adequacy, and effectiveness. In the context of an ISMS, Clause 10 sits among the certifiable ISMS requirements (clauses 4 through 10) rather than the Annex A reference controls, and it requires organizations to react to nonconformities, evaluate the need to eliminate their causes, implement corrective action, and continually improve the system. The specific sub-clause structure and wording vary by standard and edition, so practitioners should reference the applicable version when interpreting exact requirements. The evidence provided describes Clause 10 primarily in the ISO 9001 quality management context; its application to an ISO/IEC 27001 ISMS follows the same shared clause structure but should be confirmed against the relevant ISO/IEC 27001 edition.

Why it matters

Clause 10 addresses a core premise of any ISO management system: that the system should not remain static but should improve over time as circumstances, requirements, and risks change. Within the certifiable ISMS requirements (clauses 4 through 10) of ISO/IEC 27001, this clause is where an organization demonstrates that it can react to nonconformities, understand their underlying causes, take corrective action, and continually enhance the suitability, adequacy, and effectiveness of the management system. Without a functioning improvement mechanism, a management system risks becoming a documentation exercise that reflects how the organization operated at a single point in time rather than how it operates today.

For audit and certification purposes, Clause 10 is significant because auditors typically look for evidence that nonconformities are not just fixed superficially but that their causes are evaluated and, where appropriate, eliminated to prevent recurrence. The evidence describing Clause 10 in the ISO 9001 quality management context frames continual improvement as a cyclical process aimed at boosting performance and, in the quality context, increasing customer satisfaction. Because ISO management system standards share a common high-level structure, the same shared clause structure applies to an ISMS, though practitioners should confirm the exact wording against the relevant ISO/IEC 27001 edition.

It is worth noting the boundaries of this clause. Clause 10 governs how the management system improves; it does not by itself guarantee particular security outcomes or freedom from incidents. Its effectiveness depends on how rigorously an organization identifies nonconformities and follows through on corrective action, and the specific sub-clause structure and requirements vary by standard and edition.

Who it's relevant to

Compliance and ISMS managers
Those responsible for maintaining an ISO/IEC 27001 ISMS rely on Clause 10 as the mechanism for demonstrating that the system evolves over time. They typically own the nonconformity and corrective action process, track that identified issues are resolved at their cause, and maintain evidence of continual improvement that certification auditors will expect to review.
Internal auditors
Internal auditors assess how effectively the organization manages nonconformities, corrective actions, and continual improvement. Checklists and internal audit programs for the improvement clause help them evaluate whether corrective actions address root causes and whether improvement is treated as an ongoing, cyclical activity rather than a one-off task.
Certification bodies and their auditors
Because Clause 10 falls within the certifiable ISMS requirements rather than the Annex A reference controls, auditors from the accredited certification body examine it directly when assessing the management system. They typically look for evidence that the organization reacts to nonconformities, evaluates their causes, and continually improves the suitability, adequacy, and effectiveness of the system, confirmed against the applicable edition of the standard.
Senior management and process owners
Leadership and those who own individual processes are accountable for ensuring the management system does not remain static. They support improvement by allocating resources to corrective action and by fostering an ongoing effort to enhance processes as needs and circumstances change.

Inside Improvement (Clause 10)

Nonconformity and Corrective Action
Clause 10 requires the organization to react to nonconformities, evaluate the need for action to eliminate their causes so they do not recur, implement the corrective action needed, and review its effectiveness. Documented information must be retained as evidence of the nature of the nonconformities, actions taken, and results.
Continual Improvement
Clause 10 requires the organization to continually improve the suitability, adequacy, and effectiveness of the information security management system (ISMS). This is an ongoing obligation rather than a one-time activity and is one of the certifiable ISMS requirements within clauses 4 through 10.
Root Cause Analysis
Corrective action under Clause 10 typically involves determining the underlying cause of a nonconformity, not merely correcting the immediate symptom, so that similar issues are prevented from recurring. The depth of analysis generally depends on the significance of the nonconformity.
Linkage to Other ISMS Clauses
Improvement activities are commonly informed by inputs from other parts of the ISMS, such as internal audit findings, management review outputs, and monitoring and measurement results. Clause 10 closes the loop of the ISMS lifecycle by feeding lessons learned back into the management system.

Common questions

Answers to the questions practitioners most commonly ask about Improvement (Clause 10).

Does Clause 10 require a separate corrective action procedure document to satisfy an auditor?
Not necessarily. Clause 10 requires that the organization react to nonconformities, evaluate the need for action to eliminate their causes, implement any action needed, and retain documented information as evidence of the nonconformities and the actions taken. Whether that is captured in a standalone procedure or embedded within broader ISMS processes typically depends on the organization and how its certification body evaluates the arrangements. The standard requires the outcomes and the evidence, not a specific document format.
Is continual improvement in Clause 10 the same as the corrective action requirement?
No, these are distinct concepts within the clause. Corrective action addresses nonconformities that have already occurred by dealing with the cause and preventing recurrence. Continual improvement concerns the ongoing suitability, adequacy, and effectiveness of the ISMS more broadly. An organization can pursue improvements that are not tied to any nonconformity, so the two should not be treated as interchangeable.
How should a nonconformity be handled when it is identified during ISMS operation?
Typically the organization reacts to the nonconformity by taking action to control and correct it and to deal with its consequences, then evaluates whether action is needed to eliminate the cause so it does not recur. This often involves reviewing the nonconformity, determining causes, and checking whether similar nonconformities exist or could occur elsewhere. The organization then implements any needed action, reviews its effectiveness, and updates the ISMS if necessary. Documented information should be retained as evidence.
What sources commonly feed into corrective action and improvement activities?
Inputs frequently arise from internal audit findings, management review outputs, incidents and events, monitoring and measurement results, and observations from operating the ISMS. The relevant sources depend on scope and how the organization has structured its ISMS, so the mix varies from one engagement to another rather than following a single fixed list.
How does Clause 10 relate to the internal audit and management review clauses?
In most implementations these clauses work together: internal audit (Clause 9.2) and management review (Clause 9.3) surface findings and decisions, which can then trigger corrective action and improvement activity under Clause 10. This connection is often how organizations demonstrate that the ISMS is being maintained and improved over time, though the precise linkages depend on how the organization has designed its processes.
What evidence would a certification body typically expect to see for Clause 10?
Auditors generally look for retained documented information showing the nature of nonconformities, any subsequent actions taken, and the results of those actions. Evidence of how improvements were identified and acted upon may also be examined. The exact expectations depend on the certification body and the defined scope of the ISMS, and satisfying Clause 10 covers only the ISMS as scoped rather than guaranteeing any particular outcome.

Common misconceptions

Continual improvement means the ISMS must show measurable metric gains at every review cycle.
Clause 10 requires the organization to continually improve the suitability, adequacy, and effectiveness of the ISMS, but this is generally demonstrated through ongoing improvement processes and evidence of action rather than a guaranteed numeric improvement in a specific metric at every interval. How this is evaluated depends on the certification body and the defined scope.
Clause 10 corrective action is the same as the corrective controls found in Annex A.
Clause 10 is part of the certifiable ISMS requirements (clauses 4 through 10) and governs how the management system handles nonconformities and improvement. Annex A lists reference controls selected via the Statement of Applicability and informed by risk assessment; the two serve different purposes and should not be conflated.
Improvement activities are equivalent to the continuous monitoring expectations behind a SOC 2 report.
Clause 10 is specific to ISO/IEC 27001, which results in a certification issued by an accredited certification body. A SOC 2 report is an attestation examination performed by a licensed CPA firm under SSAE 18 and attests only to the controls and period covered. Mapping between the frameworks is possible but partial, and satisfying one does not automatically satisfy the other.

Best practices

Maintain a documented nonconformity and corrective action log that captures the nature of each nonconformity, the actions taken, and the results, since retaining this documented information is required as evidence.
Perform root cause analysis proportionate to the significance of each nonconformity so that corrective actions address underlying causes and reduce the likelihood of recurrence, rather than only correcting immediate symptoms.
Verify the effectiveness of corrective actions after implementation, and record the review outcome, to close the loop as Clause 10 requires.
Draw improvement inputs from internal audit findings, management review outputs, and monitoring and measurement results to keep continual improvement grounded in actual ISMS performance.
Track improvement actions to closure with assigned ownership and target timelines, and revisit open items during management review to demonstrate ongoing rather than one-time improvement.
When operating alongside a SOC 2 engagement, keep the ISO 27001 improvement processes distinct in your documentation, recognizing that any mapping between the frameworks is partial and does not create automatic equivalence.